Re: SPAM from a registrar

2014-06-05 Thread Andreas Schulze
Tom Hendrikx: > but postfix has a feature that can check the MX and NS > records of the envelope sender or hostname of the connecting ip. I know and use that. > If these are all the same, you could block connections based on those. that's intersting, no idea how to com

Domain Age

2014-06-05 Thread Andreas Schulze
Hello, today we came up with the idea to look at the domain age. It may be a criteria for otherwise perfect messages. Is there something I could ask with a domainname and receive the age as answer? Andreas

Re: writing rules howto?

2014-05-31 Thread Andreas Schulze
Andreas Schulze: Kasten, sorry -> Karsten works wonderful. I now have a list of hostnames SA find in the messagebody as new header! Thanks. Much simpler then I thought... Andreas

Re: writing rules howto?

2014-05-31 Thread Andreas Schulze
Karsten Bräckelmann: > Since SA 3.4, there are template tags which already might be all you > need. The template tags _URIHOSTS_ and _URIDOMAINS_ list all extracted > (and to be looked up) URIs, including full hostname and domain only > respectively. No path information. > > add_header all UriHo

writing rules howto?

2014-05-30 Thread Andreas Schulze
Hello, I have to get an overview on http links in a specific mail stream. My plan is to use spamassassin as it could parse message body much better then I do :-) There is a plugin URIDNSBL that could fire dns queries for every url found. That's fine for me, as the url is then in my dnsserver log.

Re: Availability of 3.4.0 release candidate 5

2014-01-13 Thread Andreas Schulze
Zitat von Mark Martinec : Curl uses environment variable http_proxy (lowercase), same as wget and LWP (libwww-perl) and similar tools. Don't know where you got the uppercase variant. Good point. The uppercase version simply did it's job. I just tried the lowercase version and sa-update work a

Re: Availability of 3.4.0 release candidate 5

2014-01-12 Thread Andreas Schulze
Hello, thanks for that great software. The only problem I found is an issue with sa-update: My network require to use a http proxy incl. authentication. To load updates I currently (sa-3.3.2) set HTTP_PROXY="..." for sa-update. That does not work anymore in 3.4 As I use curl I now have to c

Re: When/How to train bayes from user mail?

2013-10-14 Thread Andreas Schulze
Zitat von Florian Lindner : Since we move our server (and upgrade from oldstabe to stable) I want to reconsider how I organize mails serverside. Debian, MTA is postfix, MDA maildrop (like procmail), IMAP was courier, will be dovecot. if you use dovecot, maildrop is obsolete. deliver your m

Re: Available of 3.4.0 Release Candidate 3

2013-10-14 Thread Andreas Schulze
Am 11.10.2013 17:05 schrieb Kevin A. McGrail: > On behalf of the PMC, the ASF SpamAssassin Project is pleased to > announce the availability of our third release candidate for 3.4.0. Hi all! thanks for that great software first! I found two minor issues in perl documentation and attach a patch. Th

From header required

2013-07-10 Thread Andreas Schulze
Hello, Every mail MUST have exact one From header (RFC5322, 3.6). Same RFC, Section 3.6.2 allow a from header contain a list of senders (Why ???) In this case exact one sender header MUST be present and it MUST NOT a list. Are there SA Rules to score a missing or multiple from header? Does an

header field without value invalid?

2013-07-10 Thread Andreas Schulze
Hello, today I found messages with strage headers: they had an empty value. example: From: ... To: ... X-MS-TNEF-Correlator: Date: ... Is this against any rfc and could/should [not?] be rejected or used to identify spam? Thanks Andreas

Re: Interpreting an Authentication-Results: header ?

2013-04-01 Thread Andreas Schulze
Am 29.03.2013 02:36 schrieb Karsten Bräckelmann: > On Fri, 2013-03-29 at 00:56 +, John Levine wrote: > > Is there any way to tell spamassassin to look at the A-R header rather > > than trying to rerun the SPF and DKIM checks itself? in sa-3.3.2/Plugin/SPF.pm is still code like this: if ($hdr

Re: wrong RCVD_IN_PBL?

2012-11-20 Thread Andreas Schulze
Am So, 18.11.2012, 18:48 schrieb dar...@chaosreigns.com: >> are you sure? I will report it to my ISP > > No, I'm not sure, which is why I said "I believe" and "But I haven't > actually looked into those details lately. We need better documentation > of this". But I am very confident somethin

Solved: SA without Mail::SPF::Query

2012-09-07 Thread Andreas Schulze
Am Do, 6.09.2012, 13:08 schrieb Andreas Schulze: > Is it possible to use the result of the milter in the same way SA would do > with its own SPF implementation? > Than the SPF information could have an influance to the spamcore. I run smf-spf milter (sf.net/projects/smfs) and applied a

Re: SA without Mail::SPF::Query

2012-09-06 Thread Andreas Schulze
Am 06.09.2012 17:08 schrieb Ned Slider: > If your milter adds the Received-SPF header before the mail is > passed to SA then maybe you could simply write a rule to check the > Received-SPF header and score as you see appropriate. Yes, the Milter add a Received-SPF header. Could you point me to som

SA without Mail::SPF::Query

2012-09-06 Thread Andreas Schulze
Hello, for technical reasons I have no Mail::SPF::Query. So my SA has no "view" to the spf settings of an incomming mail. But I run an SPF-Milter in front of SA without Mail::SPF::Query. That Filter adds an Received-SPF header to the mails but do not reject. Is it possible to use the result of

OT: survey

2012-07-19 Thread Andreas Schulze
Hello, I like to ask you how knows/uses MTX (http://www.chaosreigns.com/mtx) Thanks for a shot response offlist. Andreas

Re: SpamTips.org: Why run your own DNS server?

2011-07-04 Thread Andreas Schulze
System#Name_servers other resolvers installable by users are - unbound ( http://unbound.net ) - dnscache ( http://cr.yp.to/dnscache.html ) - bind (off course) - http://en.wikipedia.org/wiki/Comparison_of_DNS_server_software -- Andreas Schulze

"day old bread" DNSBL

2011-05-27 Thread Andreas Schulze
anks -- Viele Grüße Andreas Schulze

Re: Testing Needed: spamassassin-3.3.2-rc1

2011-05-15 Thread Andreas Schulze
Am 15.05.2011 22:29 schrieb Andreas Schulze: > But sometimes the perldoc produces mangages with errors: and some other manpages changes ... Attached my other patch. Andreas -- # # Andreas Schulze # ht

Re: Testing Needed: spamassassin-3.3.2-rc1

2011-05-15 Thread Andreas Schulze
ail/SpamAssassin/Util/DependencyInfo.pm - lib/Mail/SpamAssassin/Util/RegistrarBoundaries.pm Attached my patch. Andreas -- # # Andreas Schulze # https://andreasschulze.de # # GnuPG Key-ID: A7DBA67F, https://andreasschulze.de/sca.

why matches FRT_SOMA and URI_HEX ?

2011-05-04 Thread Andreas Schulze
http://andreasschulze.de/tmp/quarantined What could I change, that my mails no longer matches the mentioned rules ? Thanks -- Viele Grüße Andreas Schulze

Re: "autolearn=ham" was wrong, howto retrain ?

2011-04-04 Thread Andreas Schulze
Hi, > -forget Forget a message I do sa-learn --forget ; sa-learn --spam right ? -- Viele Grüße Andreas Schulze

"autolearn=ham" was wrong, howto retrain ?

2011-04-04 Thread Andreas Schulze
Hello Im using spamassassin inside amavisd-new to filter mails. Today I noticed a mail with these headers: X-Spam-Flag: NO X-Spam-Score: -0.007 X-Spam-Level: X-Spam-Status: No, score=-0.007 tagged_above=-999 required=5 tests=[HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, MTX_NONE=0.001,

using spamhaus droplist with sa ?

2011-02-17 Thread Andreas Schulze
Hello, http://www.spamhaus.org/faq/answers.lasso?section=DROP FAQ mention as very last point to use the Spamhaus Drop list with SA. is anybody doing this and can explain it in detail ? Thanks Andreas

dkim-reputation.org / SA-Plugin

2010-09-13 Thread Andreas Schulze
dreas -- # # Andreas Schulze # https://andreasschulze.de # # GnuPG Key-ID: A7DBA67F, https://andreasschulze.de/sca.asc # GnuPG Fingerprint: 14C1 39A8 CE6D 6BE0 28C6 5652 03B5 6793 A7DB A67F # # $Id: .signature,v 1.3 2007-12-27 21:13:36 sca Exp $

abstrus warning in maillog

2010-08-23 Thread Andreas Schulze
Hello, I call SA from amavisd-new and found this warning in my logfile. Aug 23 11:36:27 taro amavis[32405]: (32405) _WARN: auto-whitelist: open of auto-whitelist file failed: Can't locate auto/NetAddr/IP/full6.al in @INC (@INC contains: /etc/perl /usr/local/lib/perl/5.10.0 /usr/local/share/perl/5

Re: IPv6 problem with sa-update

2010-08-08 Thread Andreas Schulze
On Sun, Aug 08, 2010 at 02:57:29PM -0500, Dave Funk wrote: > For some reason when you set that "options inet6" your system is not > willing to fall back to IPv4 mode (or a bug is preventing it). > That's what you need to look into (until such time as > spamassassin.apache.org gets v6 connected ;)

IPv6 problem with sa-update

2010-08-08 Thread Andreas Schulze
date runs as expected. Any suggestions ? Andreas -- ############ # # Andreas Schulze # https://andreasschulze.de # # GnuPG Key-ID: A7DBA67F, https://andreasschulze.de/sca.asc # GnuPG Fingerprint: 14C1 39A8 CE6D 6BE0 28C6 5652 03B5 6793 A7DB A67F

Headers added by spamassassin

2004-09-22 Thread Andreas Schulze
spamassassin 2.60 background: we currently test Yahoo! domainkeys. this system signs all headers an body. domainkeys assume, that headers are added only at top. Headers, added by spamassassin at the end, destroy the domainkey-signature. thanks Andreas Schulze